An Ethereum sandwich-attack bot known as JaredfromSubway.eth accumulated more than 117,000 ETH—valued at approximately $295 million—by exploiting transaction ordering on the network since March 2023. In June, the bot became a victim of the same attack mechanism when an unidentified attacker drained at least $7.5 million in ETH and stablecoins.
How the Attack Unfolded
The attacker deployed 66 fake token contracts mimicking familiar names like WETH, USDC, and USDT. The bot's automated trading logic scanned these contracts for arbitrage opportunities, inadvertently granting token-spending approvals to the attacker's malicious contracts. Once sufficient approvals accumulated, the attacker executed a coordinated sequence of transactions to drain the bot's holdings and route the proceeds through Tornado Cash. No funds have been recovered.
What Is MEV?
Maximal Extractable Value (MEV) refers to profit captured by entities who can influence which transactions land in a block and their order. Ethereum's publicly visible mempool, where pending transactions wait for inclusion, enables this by allowing anyone to observe large trades before they settle.
A sandwich attack represents the most consumer-hostile form of MEV. A bot detects a large pending swap, submits its own transaction first by paying higher gas fees, allows the victim's trade to execute at a worse price, then sells at the inflated price. The victim's slippage tolerance becomes the bot's profit margin.
Researchers described miners reordering transactions for profit as early as 2019. Flashbots, founded in 2020, created the first private auction system for MEV, moving the practice from the public mempool into an orderly bidding process. MEV-Boost, launched with Ethereum's 2022 transition to proof-of-stake, generalized this model into the default block-building method used by over 90% of validators.
Centralization Concerns
Three relays route approximately 85% to 88% of MEV-Boost blocks: relay.ultrasound.money (34.0%), Titan Relay (28.5%), and bloXroute's regulated relay (25.0%). Builder concentration is more pronounced, with Titan's builder assembling 50.3% of blocks, while Quasar and Buildernet each control around 16%.
This concentration means a single company effectively determines transaction ordering for half of Ethereum's blocks, creating a centralization risk critics have flagged since MEV-Boost's 2022 launch.
Sandwich Attacks Are Declining
Despite the scale of individual bot operations, the sandwich-attack economy has contracted significantly. Data from over 95,000 attacks shows monthly sandwich extraction falling from roughly $10 million in late 2024 to approximately $2.5 million in October 2025—a 75% decline in under a year.
Traders adopting MEV-protection tools, such as private RPCs or order-flow auctions that keep pending transactions off the public mempool, have driven much of this decline. At peak activity, sandwich attacks cost traders roughly $60 million annually, with block builders indirectly benefiting through priority fees paid by attacking bots.
Structural Solutions Ahead
Ethereum's planned Glamsterdam upgrade includes the enshrined proposer-builder separation (ePBS) module, designed to move the off-protocol MEV-Boost auction into network consensus rules. This change would remove relays as trusted intermediaries and provide validators cryptographic assurances about block content without requiring trust in builder or relay operators. Until this upgrade deploys, the MEV landscape remains characterized by ongoing uncertainty.


